Skip to content

WIP: Add provenance and compliance controls - #2786

Draft
Luis-HCC-2000 wants to merge 1 commit into
mainfrom
fix/DSYS-893
Draft

Luis-HCC-2000 wants to merge 1 commit into
mainfrom
fix/DSYS-893

Conversation

@Luis-HCC-2000

Copy link
Copy Markdown
Collaborator

Summary

Adds provenance and compliance controls for @covalent/icons.

  • Added a manifest covering all source SVGs with Figma, Git, ownership, license, policy, and review information.
  • Classified known first-party and third-party icon families.
  • Added CI validation for manifest coverage, required provenance, retrieval dates, and approved verdicts.
  • Added a provisional third-party notice and included it, the manifest, and README in the npm build.
  • Updated the icon contribution documentation.

Pending work

  • Design must confirm the provisional first-party classifications.
  • Legal/OSS must review the 19 third-party assets and provide authoritative sources, copyright holders, licenses/policies, usage restrictions, and final verdicts.
  • The manifest and third-party notice must be updated with those decisions.
  • Restricted or rejected assets must be replaced, removed, or delivered differently.

The compliance check is expected to fail while required Legal/OSS data and verdicts remain pending.

@Luis-HCC-2000

Luis-HCC-2000 commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator Author

This manifest is a proposed structure intended to facilitate Legal’s review, and legal compliance, not as a legal decision made by me.
The schema does not come from an official legal format. It is a proposal based on three needs: provenance, usage rights, and an auditable decision. Legal/OSS should confirm whether these fields are sufficient.

The Question to Legal team should be made "Do these fields provide enough evidence to determine and document whether we may copy, modify into monochrome, convert into a font glyph, and redistribute each asset through npm? Which fields are missing?"

@Luis-HCC-2000

Copy link
Copy Markdown
Collaborator Author

Here is the rationale behind every property of the schema:

Identification and Origin

  • figmaUrl: Internal design location. It helps Design recognize the icon, but does not prove ownership.
  • sourceUrl: Original authoritative source of the artwork. It allows reviewers to verify where it was obtained.
  • retrievedOn: Date when the asset was obtained or recorded. I currently use the introduction commit date as a proxy.
  • originalAuthor: Known creator of the artwork. It is optional because determining the original creator may not be possible.
  • copyrightHolder: Person or organization that owns the rights to the artwork. This may differ from the designer and is more legally relevant.

Repository Evidence

  • prUrl: PR that introduced the icon. It provides internal context.
  • commitHash: Exact point at which the icon entered the repository.
  • commitAuthor: Person who created the commit.

These three fields provide internal evidence, not proof of authorship.

Classification and Rights

  • is3rdParty: Distinguishes assets Teradata may own and license from assets whose rights belong to another entity.
  • license: SPDX identifier for the applicable copyright license.
  • licenseUrl: Authoritative evidence of that license.
  • copyrightUrl: Official copyright notice or page.
  • trademarkUrl: Official information about the registered trademark.
  • brandGuidelinesUrl: Visual and contextual rules published by the brand owner. These are separate from the copyright license.

The links are stored separately because copyright, trademark, and brand guidelines answer different legal questions.

Decision

  • verdict: Normalized result: approved, restricted, rejected, pending, or unknown.
  • verdictNotes: Conditions or reasoning, such as “may only be used in color” or “may not be redistributed.”
  • verdictAuthor: Legal/OSS reviewer who issued the decision, preserving accountability and traceability.

General Metadata

  • schemaVersion: Allows the structure to evolve without ambiguous interpretation.
  • package: Identifies the artifact to which the inventory applies.
  • The svgs/... path used as the key directly connects each record to its actual file.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant